Maze Ransomware

Description Summary

Maze ransomware group is one of the most known ransomware gangs, they targeted organizations worldwide across many industries. Security researchers believed that Maze operates as an affiliated network model. MAZE was one of the first groups that made a 'Double Extortion Attack' involved Allied Universal, in November 2019, the group leaks their victim's data in the darknet. On November 1, 2020, MAZE announced an official press release that they are closing their operation. Security researchers claim that the threat actor behind the MAZE group is 'TA2101'.

Threat Actor

TA2101; pioneered the double-extortion (leak-site) model that became the industry standard.

Technical Indicators

Encryption Extension
.<random per file>
Encryption Algorithm
ChaCha20 (files) + RSA-2048 (key wrapping)
Ransom Note Name
DECRYPT-FILES.txt
Targeted Industries
Cross-sector
First Seen
May 2019
Last Seen
November 2020 (retired; affiliates → Egregor)
Geographical Location
Worldwide

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
Exfiltration x 1 T1567 Exfiltration Over Web Service (leak site)
Initial Access x 2 T1190 Exploit Public-Facing Application
T1078 Valid Accounts